Motion Consulting Group · AI Governance

Prepared for Grace Hill.

A proposal for an AI-governance baseline. Enter the access key you were provided.

Invalid key
Motion Consulting Group · a Kelly Services company Confidential · Draft for discussion · June 2026
Proposal · AI Governance Baseline

Govern the AI your residents and regulators will ask about.

Grace Hill has put AI to work where it matters most — inside fair-housing, compliance, and resident-experience workflows. That's exactly why it deserves governance that can stand in front of an auditor, a regulator, or a buyer. We're proposing a fixed-scope baseline that inventories your AI estate, scores it honestly across three lenses, and hands you a prioritized path — in weeks, not quarters.

01 · The moment

Why now.

Your platform embeds generative AI into policy, training, and compliance content that operates across all fifty states' housing law. Regulators have been explicit: HUD's May 2024 guidance signals that the Fair Housing Act can apply to AI used in housing-related functions — and that liability may extend to technology providers, not just operators (HUD PR 24-098). At the same time, boards and private-equity owners increasingly treat documented AI governance as part of exit- and audit-readiness.

To be clear about what we are not saying: nothing in our preliminary review suggests your AI behaves improperly. What we observe — from a review of public materials only (June 2026) — is that we could not locate a published model disclosure, accuracy basis, or human-oversight description for AI features answering compliance-sensitive questions. The remedy for a control gap is straightforward and fast: document, add the right human-in-the-loop gates, and review — which is precisely what the baseline delivers.

02 · The proposal

A fixed-scope AI Inventory & Risk Baseline.

Inventory. Every AI feature, model dependency, and data access across your products and internal tooling — including shadow AI your teams may already be using.
Three-lens posture. One score each for technology rationalization, security, and AI governance — evidence-based, mapped to recognized standards (NIST AI RMF, NIST CSF 2.0, ISO/IEC 42001).
Fair-housing control review. A documented oversight basis for AI touching compliance-sensitive workflows: model disclosure, accuracy basis, human-in-the-loop gates, and a disparate-impact review path.
Cost & efficiency read. Where AI spend concentrates, what's recoverable through model right-sizing and caching discipline — governance that pays for itself.

You receive a prioritized remediation roadmap and a posture readout your leadership, owners, and counsel can act on. Where independent attestation is the goal, we prepare the evidence — we never self-certify; formal certification runs through accredited third-party bodies, and the baseline is the on-ramp to ISO/IEC 42001 readiness.

03 · How it runs

Three to four weeks, human-led, low-friction.

WeekWhat happensFrom your side
1Working session; access scoping; AI-feature and data-flow inventory begins.One technical contact; product walkthroughs.
2–3Evidence collection; three-lens scoring; fair-housing control review; cost read.Short interviews with product, security, and compliance owners.
4Readout: posture, prioritized roadmap, remediation plan, attestation path.A leadership readout session.

Every step has a human decision gate — nothing is assessed, scored, or reported without your context. Fixed fee, scoped in the first working session once we confirm the AI-system count together.

04 · Why us

We build and run — not just assess.

  • Standards-mapped method. Every control we check traces to NIST AI RMF, NIST CSF 2.0, ISO/IEC 42001, OWASP, or MITRE ATLAS — no invented checklists.
  • Honesty as policy. We mark what's real: monitoring isn't claimed live until it's connected; findings are control gaps, never unsubstantiated verdicts.
  • Delivery muscle behind the advice. When the roadmap says build, we can stand up the registry, controls, and monitoring and run them — relevant delivered work includes a HIPAA-compliant conversational-AI integration for a healthcare provider and a production agentic-AI deployment at a top-three US telecom (anonymized; references available on request).
  • Independence respected. Attestation and certification stay structurally separate from remediation — what you show your auditors holds up.
05 · Next step

One working session.

We bring the baseline instrument and a draft inventory built from your public footprint; you bring the people who know the products. Ninety minutes confirms scope, fee, and timeline — and you leave with our preliminary observations either way.

To schedule: reply through your Motion Consulting Group contact. This document is a draft for discussion — nothing here is a finding about your products; it is the case for documenting what's already true.